Data processing

How Reveu handles merchant and customer data.

This overview explains the expected roles, data categories, purposes, safeguards, subprocessors, retention practices, and privacy assistance involved in providing the Reveu Shopify application.

Last updated: 18 July 2026 Status: Pre-launch overview

Processing principles

Data used for defined product purposes.

Reveu aims to process personal information only where it is needed to provide merchant-selected features, support the service, protect the platform, or meet legal obligations.

01

Merchant-directed

Customer and order information is processed to provide services configured and requested by the merchant.

02

Purpose-limited

Information should not be used for unrelated purposes simply because it is technically available.

03

Access-controlled

Access is intended to be limited to authorised systems, providers, and people who require it for legitimate work.

04

Deletion-supported

Privacy, uninstall, and merchant-data cleanup workflows are included in the application design.

Processing overview

When a merchant uses Reveu to collect reviews, send review requests, display storefront content, import reviews, or operate conversion tools, Reveu may process information on the merchant’s behalf.

Merchant

Normally determines why customer and store information is used and which Reveu features are enabled.

Reveu

Processes information required to provide and secure the configured application services.

Shopify

Provides the commerce platform, application interfaces, store administration, and relevant merchant data.

Service providers

May provide hosting, storage, communications, monitoring, or other supporting infrastructure.

01

About this overview

This page provides general information about how Reveu expects to process personal information when providing its Shopify application.

It is intended to help prospective merchants understand the application’s data-processing model before launch.

This page does not currently:

  • Create a contract between Reveu and a merchant
  • Replace a merchant’s own privacy notice
  • Replace the Reveu Privacy Policy
  • Provide legal or regulatory advice
  • Serve as the final Data Processing Agreement
  • Confirm that every proposed provider is already in use

The final processing terms may be updated as Reveu completes infrastructure decisions, launch testing, provider selection, and merchant agreements.

02

Processing roles

Merchant as controller

A Shopify merchant will normally act as the controller for personal information relating to its customers, orders, fulfilments, products, customer communications, submitted reviews, and storefront activity.

The merchant determines matters such as:

  • Whether Reveu is installed and enabled
  • Which application features are used
  • When review-request emails are sent
  • Which customers receive communications
  • How reviews are moderated and published
  • Whether customer photos are displayed
  • Which imported reviews are accepted
  • How storefront widgets are configured
  • Whether discount and engagement tools are enabled

Reveu as processor

Reveu expects to act as a processor where it handles personal information on behalf of a merchant to provide merchant- selected application functionality.

Reveu as independent controller

Reveu may act as an independent controller for limited information it determines how and why to use for its own legitimate operations.

This may include:

  • Merchant account and administrator contact information
  • Support and service communications
  • Security and application event records
  • Website waitlist and contact-form submissions
  • Legal, fraud-prevention, and compliance records
  • Service performance and operational information

Reveu’s controller activities are described further in the Privacy Policy.

03

Expected processing scope

Depending on the features enabled by a merchant, Reveu may perform operations such as:

  • Receiving relevant Shopify store information
  • Receiving order and fulfilment events used to schedule review requests
  • Checking relevant customer communication or marketing preferences
  • Generating and validating review-request links and tokens
  • Sending merchant-configured review-request emails
  • Collecting ratings, written reviews, and customer photos
  • Matching reviews to Shopify products
  • Recording verified-purchase status
  • Moderating, publishing, hiding, or removing reviews
  • Displaying merchant replies and customer review content
  • Processing review reports and helpful votes
  • Importing review data from merchant-provided CSV files
  • Operating storefront review widgets and rating summaries
  • Operating merchant-configured discount or engagement tools
  • Providing technical support and application diagnostics
  • Processing uninstall, privacy, and deletion workflows

04

Categories of people affected

Personal information processed through Reveu may relate to:

  • Shopify merchants
  • Merchant owners and administrators
  • Merchant staff and authorised users
  • Store customers
  • Order recipients
  • People submitting product reviews
  • People appearing in customer-submitted review media
  • People interacting with review widgets
  • People submitting review reports or helpful votes
  • Support and privacy-request contacts
  • Website waitlist and contact-form users

05

Categories of information

Depending on the application features used, information may include:

Merchant information

Store identity, Shopify domain, administrator details, application configuration, theme settings, and support communications.

Customer information

Name, email address, customer or order references, and information required to send or validate review requests.

Order information

Product, order, fulfilment, purchase, delivery, and communication-preference information relevant to review collection.

Review information

Ratings, titles, written comments, images, submission dates, verification details, replies, reports, and helpful votes.

Product information

Product names, handles, IDs, variants, SKUs, images, and other information used to match and display reviews.

Technical information

Request data, event records, application errors, security information, browser details, and operational diagnostics.

Sensitive information

Reveu is not designed for merchants or customers to submit passwords, payment-card details, authentication codes, health information, government identifiers, or unnecessary special-category personal information.

06

Processing purposes

Reveu expects to process merchant-controlled information for purposes including:

  • Providing installed application functionality
  • Authenticating and associating Shopify stores
  • Collecting and managing product reviews
  • Determining verified-purchase status
  • Scheduling and sending review requests
  • Displaying reviews and ratings on storefronts
  • Supporting moderation and merchant replies
  • Importing and matching review records
  • Operating merchant-configured engagement tools
  • Preventing misuse, spam, fraud, and unauthorised access
  • Maintaining service reliability and troubleshooting
  • Responding to merchant support requests
  • Supporting privacy and deletion requests
  • Complying with applicable legal obligations

Reveu does not intend to sell merchant customer information to third parties.

07

Merchant instructions

Reveu expects to process merchant-controlled personal information only on documented instructions, except where applicable law requires different processing.

Merchant instructions may be communicated through:

  • The merchant’s installation and use of the application
  • Application settings and feature configuration
  • Review publication and moderation actions
  • Email-template and review-request settings
  • Import files and product-matching selections
  • Storefront widget configuration
  • Support requests submitted by authorised users
  • Merchant terms and the final Data Processing Agreement

Reveu may refuse an instruction where it would be technically impossible, unsafe, unlawful, inconsistent with Shopify requirements, or outside the agreed service.

08

Security measures

Reveu applies technical and organisational measures intended to protect personal information against unauthorised access, disclosure, alteration, loss, or destruction.

Current and planned measures include:

  • Verification of relevant Shopify requests and webhooks
  • Validation of public and application input
  • Restricted public access to stored submissions
  • Server-side handling of trusted application actions
  • Protection of production credentials
  • Validation of review-media references
  • Failure handling for webhooks and background processing
  • Merchant-specific data separation
  • Privacy and uninstall cleanup workflows
  • Limited access for authorised operational purposes
  • Review of service providers and infrastructure needs

Further details are available on the Security page.

09

Subprocessors and service providers

Reveu may use service providers to support hosting, storage, email delivery, security, monitoring, networking, and related application operations.

Provider categories may include:

  • Application hosting providers
  • Database and storage providers
  • Email-delivery providers
  • Media-storage or delivery providers
  • Infrastructure monitoring providers
  • Domain, DNS, and network providers
  • Customer-support or operational providers

The public website currently uses Google Firebase and Cloud Firestore for waitlist and contact-form submissions.

Shopify provides the underlying commerce platform and relevant application interfaces. Shopify’s precise legal role may depend on the processing activity and its relationship with the merchant.

Final subprocessor list

Reveu will publish or make available a confirmed application subprocessor list before the Shopify application becomes generally available. The list should identify the provider, service purpose, and relevant processing location.

10

International data transfers

Some infrastructure or service providers may process information outside the United Kingdom.

Where an international transfer is restricted by applicable data-protection law, Reveu expects to use an appropriate legal mechanism and supplementary safeguards where required.

Depending on the destination and provider, mechanisms may include:

  • UK adequacy regulations
  • The UK International Data Transfer Agreement
  • The UK Addendum to approved standard contractual clauses
  • Another legally recognised transfer mechanism

Confirmed transfer locations and mechanisms should be included in the final subprocessor information and Data Processing Agreement.

11

Retention and deletion

Application data should be retained only for as long as needed to provide the service, follow merchant instructions, protect the application, resolve disputes, or meet applicable legal obligations.

Retention may depend on:

  • Whether the merchant continues to use Reveu
  • The feature and type of information involved
  • Merchant deletion or moderation actions
  • Shopify privacy and uninstall events
  • Backup and technical recovery periods
  • Security, fraud, or incident-investigation needs
  • Applicable legal or regulatory obligations

Reveu includes workflows intended to remove relevant merchant, customer, review, media, and configuration information after applicable privacy requests or application uninstall events.

Information may be retained where deletion is technically delayed by secure backups or where continued retention is legally required. Any retained information should remain protected and should not be used for unrelated purposes.

12

Individual rights and merchant assistance

Where a merchant acts as controller, individuals should normally direct requests about their store information to that merchant.

Subject to the final DPA and applicable law, Reveu expects to provide reasonable assistance with requests involving:

  • Access to personal information
  • Correction of inaccurate information
  • Deletion of information
  • Restriction of processing
  • Data portability
  • Objections to processing
  • Withdrawal of consent where applicable
  • Questions about automated processing where relevant

Reveu may need to verify that a request comes from the relevant merchant or an authorised person before taking action.

Requests involving information controlled directly by Reveu may be sent to hello@reveu.me.

13

Personal-data incidents

If Reveu becomes aware of a confirmed personal-data breach affecting information processed for a merchant, Reveu expects to provide the merchant with relevant information without undue delay, subject to applicable law and the final DPA.

Information may include:

  • The nature of the incident
  • The systems or information affected
  • The approximate scope, where known
  • Likely consequences, where they can be assessed
  • Containment or remediation steps
  • Information reasonably needed for the merchant’s response

Reveu may also work with relevant providers, legal advisers, regulators, or law-enforcement authorities where appropriate.

14

Data-protection complaints

A person may contact Reveu if they believe Reveu has handled their personal information in a way that does not comply with applicable data-protection law.

Complaints may be submitted by email or through the Reveu contact form by selecting “Privacy and data.”

Reveu will:

  • Provide a direct way to submit the complaint
  • Acknowledge receipt within 30 days
  • Take appropriate steps to investigate without undue delay
  • Request additional information where reasonably necessary
  • Keep the complainant appropriately informed
  • Communicate the outcome without undue delay

Where the complaint relates primarily to information controlled by a Shopify merchant, Reveu may direct the person to that merchant or work with the merchant to investigate the issue.

Privacy and data complaints hello@reveu.me